diff --git a/tests/Feature/BackUrlSanitizeForLinksShouldRejectUnsafeBackTest.php b/tests/Feature/BackUrlSanitizeForLinksShouldRejectUnsafeBackTest.php new file mode 100644 index 0000000..4c336ed --- /dev/null +++ b/tests/Feature/BackUrlSanitizeForLinksShouldRejectUnsafeBackTest.php @@ -0,0 +1,49 @@ + ['', ''], + 'no_slash_prefix' => ['admin', ''], + 'protocol_relative' => ['//evil.com/x', ''], + 'absolute_url' => ['https://evil.com/x', ''], + 'quote_injection' => ['/admin?x=" onclick="alert(1)', ''], + 'angle_injection' => ['/admin?